2026 CVE Vulnerabilities

44,067 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-67688CRITICAL9.8ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module....
CVE-2026-67687HIGH8.8Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol...
CVE-2026-67622CRITICAL9.9Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration th...
CVE-2026-67621HIGH7.6Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perf...
CVE-2026-67434HIGH7.3PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13....
CVE-2026-67422HIGH7.5pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, ...
CVE-2026-65400CRITICAL9.8An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS...
CVE-2026-64677MEDIUM5.9Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not ...
CVE-2026-64665HIGH8.1Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was ...
CVE-2026-64664MEDIUM4.3Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont...
CVE-2026-64663MEDIUM6.5Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-sup...
CVE-2026-64662MEDIUM6.5Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont...
CVE-2026-64655LOW2.1GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify  builds the certificate S...
CVE-2026-64654MEDIUM5.3GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed ex...
CVE-2026-64653MEDIUM5.1GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable pat...
CVE-2026-64652LOW3.3GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characte...
CVE-2026-63725HIGH8.6sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a ta...
CVE-2026-63637HIGH8.6Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter....
CVE-2026-62857HIGH8.8Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the...
CVE-2026-61632MEDIUM5.3PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.2...
CVE-2026-5857CRITICAL9.2Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking ...
CVE-2026-5856HIGH7.1Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no pack...
CVE-2026-5855HIGH8.7Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer lengt...
CVE-2026-5336MEDIUM6.8The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template ren...
CVE-2026-54717MEDIUM5.4Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now